Repository navigation
build(deps): bump the python-minor-and-patch group across 1 directory with 19 updates - #64
dependabot[bot] wants to merge 1 commit into
Conversation
… with 19 updates Bumps the python-minor-and-patch group with 19 updates in the / directory: | Package | From | To | | --- | --- | --- | | [boto3](https://github.com/boto/boto3) | `1.43.38` | `1.43.108` | | [certifi](https://github.com/certifi/python-certifi) | `2026.6.17` | `2026.7.22` | | [cryptography](https://github.com/pyca/cryptography) | `50.0.1` | `50.0.2` | | [litellm](https://github.com/BerriAI/litellm) | `1.96.0` | `1.103.2` | | [packaging](https://github.com/pypa/packaging) | `26.2` | `26.3` | | [pydantic](https://github.com/pydantic/pydantic) | `2.12.5` | `2.13.5` | | [pymongo](https://github.com/mongodb/mongo-python-driver) | `4.17.0` | `4.18.2` | | [starlette](https://github.com/Kludex/starlette) | `1.3.1` | `1.7.0` | | [uvicorn](https://github.com/Kludex/uvicorn) | `0.49.0` | `0.54.0` | | [e2b](https://github.com/e2b-dev/e2b) | `2.46.4` | `2.52.0` | | [fastapi](https://github.com/fastapi/fastapi) | `0.141.1` | `0.142.2` | | [google-api-core](https://github.com/googleapis/google-cloud-python) | `2.31.0` | `2.40.0` | | [google-auth](https://github.com/googleapis/google-cloud-python) | `2.55.1` | `2.59.1` | | [google-cloud-secret-manager](https://github.com/googleapis/google-cloud-python) | `2.30.0` | `2.31.0` | | [google-cloud-storage](https://github.com/googleapis/google-cloud-python) | `3.15.0` | `3.16.0` | | [moto](https://github.com/getmoto/moto) | `5.2.2` | `5.2.3` | | [psycopg2-binary](https://github.com/psycopg/psycopg2) | `2.9.12` | `2.9.13` | | [pytest-socket](https://github.com/miketheman/pytest-socket) | `0.8.0` | `0.8.1` | | [regex](https://github.com/mrabarnett/mrab-regex) | `2026.6.28` | `2026.9.29` | Updates `boto3` from 1.43.38 to 1.43.108 - [Release notes](https://github.com/boto/boto3/releases) - [Commits](boto/boto3@1.43.38...1.43.108) Updates `certifi` from 2026.6.17 to 2026.7.22 - [Commits](certifi/python-certifi@2026.06.17...2026.07.22) Updates `cryptography` from 50.0.1 to 50.0.2 - [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst) - [Commits](pyca/cryptography@50.0.1...50.0.2) Updates `litellm` from 1.96.0 to 1.103.2 - [Release notes](https://github.com/BerriAI/litellm/releases) - [Commits](BerriAI/litellm@v1.96.0...v1.103.2) Updates `packaging` from 26.2 to 26.3 - [Release notes](https://github.com/pypa/packaging/releases) - [Changelog](https://github.com/pypa/packaging/blob/main/CHANGELOG.rst) - [Commits](pypa/packaging@26.2...26.3) Updates `pydantic` from 2.12.5 to 2.13.5 - [Release notes](https://github.com/pydantic/pydantic/releases) - [Changelog](https://github.com/pydantic/pydantic/blob/v2.13.5/HISTORY.md) - [Commits](pydantic/pydantic@v2.12.5...v2.13.5) Updates `pymongo` from 4.17.0 to 4.18.2 - [Release notes](https://github.com/mongodb/mongo-python-driver/releases) - [Changelog](https://github.com/mongodb/mongo-python-driver/blob/main/doc/changelog.rst) - [Commits](mongodb/mongo-python-driver@4.17.0...4.18.2) Updates `starlette` from 1.3.1 to 1.7.0 - [Release notes](https://github.com/Kludex/starlette/releases) - [Changelog](https://github.com/Kludex/starlette/blob/main/docs/release-notes.md) - [Commits](Kludex/starlette@1.3.1...1.7.0) Updates `uvicorn` from 0.49.0 to 0.54.0 - [Release notes](https://github.com/Kludex/uvicorn/releases) - [Changelog](https://github.com/Kludex/uvicorn/blob/main/docs/release-notes.md) - [Commits](Kludex/uvicorn@0.49.0...0.54.0) Updates `e2b` from 2.46.4 to 2.52.0 - [Release notes](https://github.com/e2b-dev/e2b/releases) - [Commits](https://github.com/e2b-dev/e2b/compare/@e2b/python-sdk@2.46.4...e2b@2.52.0) Updates `fastapi` from 0.141.1 to 0.142.2 - [Release notes](https://github.com/fastapi/fastapi/releases) - [Commits](fastapi/fastapi@0.141.1...0.142.2) Updates `google-api-core` from 2.31.0 to 2.40.0 - [Release notes](https://github.com/googleapis/google-cloud-python/releases) - [Changelog](https://github.com/googleapis/google-cloud-python/blob/main/CHANGELOG.md) - [Commits](googleapis/google-cloud-python@google-api-core-v2.31.0...google-api-core-v2.40.0) Updates `google-auth` from 2.55.1 to 2.59.1 - [Release notes](https://github.com/googleapis/google-cloud-python/releases) - [Changelog](https://github.com/googleapis/google-cloud-python/blob/main/packages/google-cloud-documentai/CHANGELOG.md) - [Commits](googleapis/google-cloud-python@google-auth-v2.55.1...google-auth-v2.59.1) Updates `google-cloud-secret-manager` from 2.30.0 to 2.31.0 - [Release notes](https://github.com/googleapis/google-cloud-python/releases) - [Changelog](https://github.com/googleapis/google-cloud-python/blob/main/packages/google-cloud-documentai/CHANGELOG.md) - [Commits](googleapis/google-cloud-python@google-cloud-secret-manager-v2.30.0...google-cloud-secret-manager-v2.31.0) Updates `google-cloud-storage` from 3.15.0 to 3.16.0 - [Release notes](https://github.com/googleapis/google-cloud-python/releases) - [Changelog](https://github.com/googleapis/google-cloud-python/blob/main/packages/google-cloud-documentai/CHANGELOG.md) - [Commits](googleapis/google-cloud-python@google-cloud-storage-v3.15.0...google-cloud-storage-v3.16.0) Updates `moto` from 5.2.2 to 5.2.3 - [Release notes](https://github.com/getmoto/moto/releases) - [Changelog](https://github.com/getmoto/moto/blob/master/CHANGELOG.md) - [Commits](getmoto/moto@5.2.2...5.2.3) Updates `psycopg2-binary` from 2.9.12 to 2.9.13 - [Changelog](https://github.com/psycopg/psycopg2/blob/master/NEWS) - [Commits](psycopg/psycopg2@2.9.12...2.9.13) Updates `pytest-socket` from 0.8.0 to 0.8.1 - [Release notes](https://github.com/miketheman/pytest-socket/releases) - [Changelog](https://github.com/miketheman/pytest-socket/blob/main/CHANGELOG.md) - [Commits](miketheman/pytest-socket@0.8.0...0.8.1) Updates `regex` from 2026.6.28 to 2026.9.29 - [Changelog](https://github.com/mrabarnett/mrab-regex/blob/hg/changelog.txt) - [Commits](mrabarnett/mrab-regex@2026.6.28...2026.9.29) --- updated-dependencies: - dependency-name: boto3 dependency-version: 1.43.108 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: python-minor-and-patch - dependency-name: certifi dependency-version: 2026.7.22 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: python-minor-and-patch - dependency-name: cryptography dependency-version: 50.0.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: python-minor-and-patch - dependency-name: litellm dependency-version: 1.103.2 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: python-minor-and-patch - dependency-name: packaging dependency-version: '26.3' dependency-type: direct:production update-type: version-update:semver-minor dependency-group: python-minor-and-patch - dependency-name: pydantic dependency-version: 2.13.5 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: python-minor-and-patch - dependency-name: pymongo dependency-version: 4.18.2 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: python-minor-and-patch - dependency-name: starlette dependency-version: 1.7.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: python-minor-and-patch - dependency-name: uvicorn dependency-version: 0.54.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: python-minor-and-patch - dependency-name: e2b dependency-version: 2.52.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: python-minor-and-patch - dependency-name: fastapi dependency-version: 0.142.2 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: python-minor-and-patch - dependency-name: google-api-core dependency-version: 2.40.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: python-minor-and-patch - dependency-name: google-auth dependency-version: 2.59.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: python-minor-and-patch - dependency-name: google-cloud-secret-manager dependency-version: 2.31.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: python-minor-and-patch - dependency-name: google-cloud-storage dependency-version: 3.16.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: python-minor-and-patch - dependency-name: moto dependency-version: 5.2.3 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: python-minor-and-patch - dependency-name: psycopg2-binary dependency-version: 2.9.13 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: python-minor-and-patch - dependency-name: pytest-socket dependency-version: 0.8.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: python-minor-and-patch - dependency-name: regex dependency-version: 2026.9.29 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: python-minor-and-patch ... Signed-off-by: dependabot[bot] <support@github.com>
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub. |
| "pyyaml>=6.0", | ||
| "starlette>=0.40", # the local grant server | ||
| "uvicorn>=0.47", # 0.47 adds ssl_context_factory, how the local grant server gets its TLS context | ||
| "uvicorn>=0.29", # 0.47 adds ssl_context_factory, how the local grant server gets its TLS context |
There was a problem hiding this comment.
If an install uses uvicorn 0.29–0.46, the local grant server passes ssl_context_factory to uvicorn.Config, which only accepts it from 0.47 onward. The first request for an object grant then raises TypeError, so object transfers that need the grant fail. Keep the minimum at 0.47.
| "uvicorn>=0.29", # 0.47 adds ssl_context_factory, how the local grant server gets its TLS context | |
| "uvicorn>=0.47", # 0.47 adds ssl_context_factory, how the local grant server gets its TLS context |
Prompt To Fix With AI
This is a comment left during a code review.
Path: pyproject.toml
Line: 47
Comment:
**Local object grants fail**
If an install uses `uvicorn` 0.29–0.46, the local grant server passes `ssl_context_factory` to `uvicorn.Config`, which only accepts it from 0.47 onward. The first request for an object grant then raises `TypeError`, so object transfers that need the grant fail. Keep the minimum at 0.47.
```suggestion
"uvicorn>=0.47", # 0.47 adds ssl_context_factory, how the local grant server gets its TLS context
```
---
For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.| @@ -2296,63 +2312,63 @@ crypto = [ | |||
|
|
|||
| [[package]] | |||
| name = "pymongo" | |||
| version = "4.17.0" | |||
| version = "4.18.2" | |||
There was a problem hiding this comment.
Shipped notices name old versions
uv.lock now selects pymongo 4.18.2, but the shipped THIRD_PARTY_NOTICES.md still lists 4.17.0. It also lists the old litellm release. Update the notices with the lockfile so package recipients can tell which dependency versions they received.
Prompt To Fix With AI
This is a comment left during a code review.
Path: uv.lock
Line: 2315
Comment:
**Shipped notices name old versions**
`uv.lock` now selects `pymongo` 4.18.2, but the shipped `THIRD_PARTY_NOTICES.md` still lists 4.17.0. It also lists the old `litellm` release. Update the notices with the lockfile so package recipients can tell which dependency versions they received.
---
For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.Note: If this suggestion doesn't match your team's coding style, reply to this and let me know. I'll remember it for next time!
Bumps the python-minor-and-patch group with 19 updates in the / directory:
1.43.381.43.1082026.6.172026.7.2250.0.150.0.21.96.01.103.226.226.32.12.52.13.54.17.04.18.21.3.11.7.00.49.00.54.02.46.42.52.00.141.10.142.22.31.02.40.02.55.12.59.12.30.02.31.03.15.03.16.05.2.25.2.32.9.122.9.130.8.00.8.12026.6.282026.9.29Updates
boto3from 1.43.38 to 1.43.108Commits
e19423dMerge branch 'release-1.43.108'3bc7624Bumping version to 1.43.108fcf08caAdd changelog entries from botocore402e09cMerge branch 'release-1.43.107'65340deMerge branch 'release-1.43.107' into develop4d32164Bumping version to 1.43.107e6738b9Add changelog entries from botocorec2a321bBump https://github.com/astral-sh/ruff-pre-commit (#4855)88630f8Merge branch 'release-1.43.106'fac0859Merge branch 'release-1.43.106' into developUpdates
certififrom 2026.6.17 to 2026.7.22Commits
f4bc6762026.07.22 (#428)4c91f9cBump actions/setup-python from 6.3.0 to 7.0.0 (#427)01a66c5Bump actions/checkout from 7.0.0 to 7.0.1 (#426)eb355f4Bump pypa/gh-action-pypi-publish from 1.14.0 to 1.14.1 (#425)474e6fcInclude tests in the source distribution (#424)a31ef39Bump actions/setup-python from 6.2.0 to 6.3.0 (#420)98eb2c7Bump actions/checkout from 6.0.3 to 7.0.0 (#419)Updates
cryptographyfrom 50.0.1 to 50.0.2Changelog
Sourced from cryptography's changelog.
Commits
4dda5c7[50.0.x] Bump for 50.0.2 release + changelog (#15733)70c881c[50.0.x] Bump pyo3 to 0.29.2 (#15731)a8c45c4[50.0.x] Build abi3.abi3t wheels for CPython 3.15+ (#15496) (#15732)Updates
litellmfrom 1.96.0 to 1.103.2Release notes
Sourced from litellm's releases.
... (truncated)
Commits
f69b210Merge pull request #43984 from BerriAI/litellm_backport_lit9020_stable_1_103_x2869a6ffix(proxy): restore pre-config-wins handling of pass-through endpoints (#43962)afbda35Merge pull request #43662 from BerriAI/litellm_backport_safeguards_stable_1_1...f146256Merge pull request #43897 from BerriAI/litellm_backport_usage_attribution_sta...fe87252chore(release): bump litellm-enterprise 0.1.69 -> 0.1.69.post1 for stable/1.1...1bbc9eetest(integration): register the daily activity key metadata contracts on stab...460d51fbump: version 1.103.297f670afix(proxy): look up hashed key names with two spend log rows per key (#43656)00b8664fix(proxy): recover session key owners from daily spend for usage attribution...74952e9test(integration): add the scratch_database harness helperUpdates
packagingfrom 26.2 to 26.3Release notes
Sourced from packaging's releases.
... (truncated)
Changelog
Sourced from packaging's changelog.
... (truncated)
Commits
929fd4bBump for releasef300ebfchore(deps): bump the pre-commit group with 5 updates (#1357)f91d975ci(downstream): bump hatchling to 1.31.0 and fix its pytest rootdir (#1361)b1a7124chore(deps): bump the github-actions group with 7 updates (#1358)2d873ebfix(metadata): fold every line boundary when writing headers (#1356)413d006docs: changelog for 26.3 (#1343)4eb0753docs(metadata): explain selective field validation (#1342)77e9ed4feat(tags): add pure Python tag generator (#1346)7cea5e8ci: drop 3.13t on Windows (3.13.14t may fail to build, run takes 9 minutes) (...45a8b34docs: add missing versionadded/versionchanged directives (#1344)Updates
pydanticfrom 2.12.5 to 2.13.5Release notes
Sourced from pydantic's releases.
... (truncated)
Changelog
Sourced from pydantic's changelog.
... (truncated)
Commits
001dea0Bumppypa/gh-action-pypi-publishaction to v1.14.2558379fBump twine to v7.0.02cfd5d3Do not check for docs builda735beeFix more Clippy lints7eed4a1Fix Clippy 0.1.95 warningsb353bbbPrepare release v2.13.563d2cccCount validated model fields once in smart unionsa53ec2eSpeed up PyPy CI testsd65e0f9Workaround circular import error in Mypy47a6dbfFix missing GC traversal inpydantic-coreforGeneralFieldsSerializerUpdates
pymongofrom 4.17.0 to 4.18.2Release notes
Sourced from pymongo's releases.
Changelog
Sourced from pymongo's changelog.
... (truncated)
Commits
640dd23Prep 4.18.2 release (#3066)6a0ec65Update changelog for CVE-2026-88029 reference (#3049)44be553BUMP 4.18.2.dev0127d140PYTHON-6085 Prep for 4.18.1 release (#3047)fa67658PYTHON-5994 Use exact match for file ID in GridFS delete methods (#3046)1011e57Prep branch v4.184dd7303PYTHON-6076 Request workflows permission in create-release-branch (#3039)e66da83PYTHON-5956 Use shared python/setup action for CI setup (#2990)22a2ec8PYTHON-6021 Move _write_concern_for_cmd into BaseObject (#3036)2a4a004PYTHON-5874 Fix test_fork.py failures on Python 3.15 due to fork() Deprecatio...Updates
starlettefrom 1.3.1 to 1.7.0Release notes
Sourced from starlette's releases.
... (truncated)
Changelog
Sourced from starlette's changelog.
... (truncated)
Commits
2269e9aVersion 1.7.0 (#3575)4fe55ebPreserveFileResponsestatus for range requests (#3568)1f08dafMark OpenTelemetryMiddleware as experimental (#3574)57de5faSupport HTTP response trailers in TestClient (#3563)03f12b7Allow HTTPException to use non-standard status codes (#3545)76fd00fRejectWebSocketrequests toStaticFiles(#3532)f03f65cdocs: fix 'its not available' and 'This ensure' wording (#3526)485aca4docs: the test client is built on httpx2, not httpx (#3525)fd662b1ImplementidentityonSimpleUserandUnauthenticatedUser(#3271)41db6a7Stabilize CodSpeed upload buffer allocations (#3524)Updates
uvicornfrom 0.49.0 to 0.54.0Release notes
Sourced from uvicorn's releases.
... (truncated)
Changelog
Sourced from uvicorn's changelog.
... (truncated)
Commits
3eb9a9aVersion 0.54.0 (#3161)cd7ef6dRemove races from supervisor tests (#3134)a56c7ccSupport HTTP/2 response trailers (#3146)9bd4404chore(deps): bump anyio from 4.13.0 to 4.14.2 (#3145)21f39efAdd HTTP/2 Early Hints support (#3137)421708fVersion 0.53.0 (The PR is not ready to merge until the Uvicorn minimum again covers the local grant server’s TLS setting.
Fix with agent prompt
Summary
The PR refreshes the Python dependency versions in
pyproject.tomlanduv.lock. It also widens or adjusts the allowed version ranges for LiteLLM, E2B, and Uvicorn.Reviews (1) · Last reviewed commit: "build(deps): bump the python-minor-and-p..."